Visualização normal

Antes de ontemStream principal
  • ✇Cybersecurity News
  • Claude Fable 5 Intelligence Drop Sparks Concerns Do Son
    Developers report a Claude Fable 5 intelligence drop. Anthropic clarifies that Claude Code effort level scores reflect API configuration testing. Related Posts: OneDrive Folder Exclusions Roll Out for Development Environments OpenAI Advocates Stricter California AI Regulations LinkedIn AI Slop Reduction: A Necessary Course Correction The post Claude Fable 5 Intelligence Drop Sparks Concerns appeared first on Daily CyberSecurity.
     
  • ✇Unit 42
  • ChainDrop: Inside a Self-Propagating npm Worm Unit 42
    Analysis of ChainDrop, an npm supply chain worm extracting GitHub Actions runner secrets and using Ethereum smart contracts for C2 routing. The post ChainDrop: Inside a Self-Propagating npm Worm appeared first on Unit 42.
     

ChainDrop: Inside a Self-Propagating npm Worm

6 de Agosto de 2026, 19:26

Analysis of ChainDrop, an npm supply chain worm extracting GitHub Actions runner secrets and using Ethereum smart contracts for C2 routing.

The post ChainDrop: Inside a Self-Propagating npm Worm appeared first on Unit 42.

“I’m Allowed”: Hackers Use Simple Claims to Bypass AI Guardrails

Cisco Talos found hackers using simple authorization claims to bypass AI guardrails, build DDoS attack tools, steal credentials and access live camera services.

Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks

30 de Julho de 2026, 07:00

Unit 42 details a Chinese speaking threat actor combining autonomous AI scanning across seven vulnerabilities with manual exploitation. Read more.

The post Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks appeared first on Unit 42.

Os usuários podem monitorar outras pessoas em tempo real para fins logísticos ou de segurança

CCTV: como uma ferramenta de código aberto expôs a localização de usuários do Telegram | OSINT Brasil RDS Consultoria / OSINT Brasil">

$  

OSINT · Privacidade Digital · Contrainteligência

CCTV: a ferramenta de código aberto que transformou o Telegram em um mapa de rastreamento em tempo real

Como o recurso "Pessoas Próximas" virou vetor de geolocalização, o que a repercussão global do caso ensina sobre exposição digital, e o que diz a lei brasileira sobre esse tipo de monitoramento.

Análise Analítico de Dados · OSINT Brasil ·
"Quem não controla a informação, vira alvo dela." — Rogério Souza

O que foi o caso CCTV

Em 2024, um projeto de código aberto batizado Close-Circuit Telegram Vision (CCTV) ganhou notoriedade internacional por demonstrar, na prática, uma fragilidade conceitual em um recurso que milhões de pessoas usam sem pensar duas vezes: o "Pessoas Próximas" do Telegram, criado originalmente para sugerir contatos e canais locais.

A ferramenta automatizava um processo que, isoladamente, qualquer usuário do Telegram poderia repetir manualmente: consultar a distância aproximada informada pelo aplicativo entre a conta que faz a busca e outras contas próximas. Ao repetir essa consulta a partir de múltiplos pontos simulados, era possível aplicar um raciocínio de trilateração — a mesma lógica geométrica usada por GPS e por técnicas clássicas de GEOINT — para convergir sobre a localização real de um alvo, com precisão relatada na faixa de 50 a 100 metros.

Ponto de virada: em 6 de setembro de 2024, o Telegram desativou o recurso "Pessoas Próximas" em nível de plataforma. Isso encerrou de forma definitiva o funcionamento de todas as ferramentas construídas sobre esse vetor, incluindo o CCTV. O caso ilustra um padrão recorrente em OSINT: recursos de conveniência de UX frequentemente carregam superfícies de exposição que só se tornam visíveis quando alguém as instrumentaliza publicamente.

Por que o caso repercutiu tanto

A cobertura do caso não ficou restrita a um nicho técnico. Veículos e comunidades de segurança em pelo menos quatro idiomas noticiaram o tema — da imprensa especializada em tecnologia à imprensa investigativa russa, passando por publicações de segurança na Itália e na Espanha. O padrão de repercussão é um indicador clássico de que a ferramenta tocou em uma preocupação real e generalizada: a sensação de que aplicativos de mensageria, mesmo os que se posicionam como focados em privacidade, podem carregar funcionalidades cujo risco não é comunicado com clareza ao usuário final.

Do ponto de vista de quem trabalha com Threat Intelligence e investigação digital defensiva, o episódio é um estudo de caso relevante sobre três frentes que se cruzam:

  • Superfície de exposição por design — recursos pensados para conveniência (encontrar pessoas/canais perto de você) podem ser reaproveitados como primitivas de rastreamento quando automatizados em escala.
  • Assimetria entre usuário comum e agente malicioso — a maioria dos usuários não tem ideia de que uma funcionalidade de "descoberta local" pode ser convertida em ferramenta de perseguição (stalking) por qualquer pessoa com conhecimento básico de scripting.
  • Velocidade de resposta da plataforma — o desligamento do recurso, embora tardio em relação à circulação pública da ferramenta, mostra que pressão pública e cobertura de imprensa continuam sendo um dos poucos mecanismos efetivos de correção rápida quando não há regulação específica em tempo real.

A lógica técnica, em nível conceitual

Sem reproduzir instruções operacionais — o que não é o objetivo deste artigo nem de qualquer conteúdo produzido pela OSINT Brasil —, vale entender a lógica subjacente para fins de conscientização defensiva:

  1. O aplicativo informa uma distância aproximada entre duas contas quando ambas têm o recurso de descoberta local ativo.
  2. Repetindo essa consulta a partir de coordenadas de referência diferentes (um processo de deslocamento simulado), obtêm-se múltiplos "raios" de distância até o mesmo alvo.
  3. A interseção geométrica desses raios — o mesmo princípio usado por sistemas de posicionamento por satélite — converge para uma área cada vez menor, até aproximar a localização real com margem de dezenas de metros.

Essa lógica não é exclusiva do Telegram. Qualquer serviço que exponha "distância até outro usuário" sem limitar a granularidade, a frequência de consulta ou o comportamento automatizado (via API) está sujeito ao mesmo tipo de abuso. É por isso que, em auditorias de exposição digital, um dos pontos de verificação padrão da metodologia OSINT Brasil é justamente mapear quais aplicativos do cliente expõem, mesmo que de forma aproximada, sinais de proximidade geográfica.

Enquadramento jurídico no Brasil

Ferramentas com essa finalidade — rastrear a localização de uma pessoa sem consentimento, para fins de monitoramento, controle ou vigilância — esbarram em pelo menos três frentes do ordenamento jurídico brasileiro:

Lei do Stalking (Lei nº 14.132/2021)

Incluiu no Código Penal o crime de perseguição (art. 147-A), que criminaliza perseguir alguém reiteradamente, por qualquer meio, ameaçando sua integridade física ou psicológica, restringindo sua capacidade de locomoção ou, de qualquer forma, invadindo ou perturbando sua esfera de liberdade ou privacidade. O uso de uma ferramenta de geolocalização não consentida para monitorar deslocamentos de uma pessoa se encaixa diretamente nesse tipo penal quando há reiteração e finalidade de vigilância.

LGPD (Lei nº 13.709/2018)

Dados de geolocalização são dados pessoais e, dependendo do contexto (por exemplo, quando revelam rotina, endereço residencial ou deslocamentos que permitem inferir características sensíveis), podem se aproximar do regime mais rigoroso do art. 11. O tratamento sem base legal — e monitoramento oculto de terceiros certamente não se enquadra nas hipóteses do art. 7º — configura ilícito civil, sujeito a indenização por danos morais e, no caso de agentes de tratamento formais, a sanções administrativas da ANPD.

Marco Civil da Internet (Lei nº 12.965/2014)

Reforça a proteção à privacidade e à intimidade como princípios da disciplina do uso da internet no Brasil (art. 3º, incisos II e III), servindo de base complementar em ações que discutam responsabilidade de provedores de aplicação diante de vazamentos de funcionalidade que facilitem rastreamento não consentido.

Nota sobre jurisprudência recente: tribunais superiores brasileiros vêm consolidando, ao longo de 2025 e 2026, o entendimento de que o tratamento de dados pessoais sem base legal adequada gera dever de indenizar quando há exposição concreta de intimidade — e o STJ tem atuado para uniformizar decisões sobre compartilhamento indevido de dados pessoais, inclusive sob o CPC (arts. 927 e 1.036), buscando reduzir divergências entre tribunais de segunda instância. Na esfera criminal, o STF já assentou que provas obtidas a partir de dados de geolocalização ou conteúdo telemático sem autorização judicial são nulas em investigações penais — precedente que reforça, por analogia, a ilicitude de qualquer coleta de localização à margem do devido processo.

Lições defensivas: como reduzir sua superfície de exposição

Vetor de riscoAção recomendada
Recursos de "descoberta por proximidade"Desative funcionalidades de geolocalização social sempre que não forem estritamente necessárias.
Compartilhamento de localização em tempo realRestrinja a contatos específicos e por tempo limitado, nunca de forma permanente.
Metadados em fotos e storiesRemova metadados de GPS antes de publicar (revisão EXIF), especialmente em conteúdo próximo à residência ou local de trabalho.
Apps de terceiros com permissão de localizaçãoAudite periodicamente quais aplicativos têm acesso contínuo (não apenas "durante o uso").
Padrões de rotina expostos publicamenteEvite postar em tempo real; publique com atraso quando o conteúdo revelar padrões de deslocamento previsíveis.

Cenários prospectivos

O desligamento do recurso pelo Telegram resolve o vetor específico do CCTV, mas não elimina o problema estrutural. Alguns cenários prováveis para os próximos ciclos:

  • Migração do vetor para outras plataformas — qualquer aplicativo que ainda exponha distância aproximada entre usuários (redes de namoro, apps de encontros, redes sociais de nicho) permanece candidato a réplicas conceituais da mesma técnica.
  • Pressão regulatória crescente — a tendência, tanto na União Europeia (DSA/GDPR) quanto no Brasil (agenda da ANPD), é de exigir de plataformas testes de "privacy by design" mais rigorosos antes do lançamento de recursos sociais baseados em proximidade.
  • Judicialização de casos concretos — é razoável esperar um aumento de ações envolvendo a Lei do Stalking combinadas a pedidos de indenização sob a LGPD, à medida que vítimas de monitoramento digital não consentido buscam reparação civil e criminal simultaneamente.
  • Uso em due diligence e investigação defensiva — o caso já se consolidou como referência didática em treinamentos de OSINT e threat intelligence, justamente pelo caráter reproduzível do princípio geométrico por trás da técnica.

Conclusão

O caso CCTV não foi apenas sobre uma ferramenta específica — foi sobre como um detalhe aparentemente inofensivo de design de produto pode se transformar em vetor de vigilância em escala quando cai nas mãos certas (ou erradas). Para profissionais de segurança da informação, investigação digital e compliance, o episódio reforça uma regra permanente: toda funcionalidade que revela proximidade, distância ou presença de um usuário é, por definição, uma funcionalidade de geolocalização — e deve ser tratada com o mesmo rigor jurídico e técnico que qualquer outro dado sensível.

Conteúdo produzido pela OSINT Brasil para fins de conscientização em segurança da informação e investigação digital defensiva. Este artigo não reproduz nem incentiva o uso de ferramentas de rastreamento não consentido de pessoas, prática que pode configurar crime de perseguição (art. 147-A do Código Penal) e ilícito civil sob a LGPD.
  • ✇Security Affairs
  • Claude Code and DeepSeek Powered Chinese Cyber Espionage Campaign Pierluigi Paganini
    Chinese actors used Claude Code and DeepSeek to automate attacks that breached government systems and targeted financial firms. Hunt.io researchers stumbled onto an active intrusion campaign in June 2026 while pivoting on known TencShell command-and-control infrastructure. A single HTTP header fingerprint on port 1111 led them to 13 Hong Kong-based servers and, on one of them, an open directory containing 2,431 files and 80 subdirectories: victim source code, custom exploit scripts, cloned l
     

Claude Code and DeepSeek Powered Chinese Cyber Espionage Campaign

16 de Julho de 2026, 06:16

Chinese actors used Claude Code and DeepSeek to automate attacks that breached government systems and targeted financial firms.

Hunt.io researchers stumbled onto an active intrusion campaign in June 2026 while pivoting on known TencShell command-and-control infrastructure. A single HTTP header fingerprint on port 1111 led them to 13 Hong Kong-based servers and, on one of them, an open directory containing 2,431 files and 80 subdirectories: victim source code, custom exploit scripts, cloned login pages, and operator logs with notes written in Simplified Chinese. Someone left the door open. Researchers walked right in.

What made this find unusual wasn’t just the scope of the targeting. It was the tooling.

“What caught our attention was the tooling behind it. Claude Code and DeepSeek-v4-pro ran as working parts of the intrusion, not tools off to the side. They handled reasoning for bypass techniques, reworked exploits after failed attempts, and built the phishing pages used to harvest credentials.” reads the report published by Hunt.io. “That puts this campaign alongside Anthropic’s November 2025 disclosure of a China-linked operation that used Claude Code to automate large-scale intrusions.”

This puts the campaign alongside Anthropic’s own November 2025 disclosure of a China-linked operation that used Claude Code to automate large-scale intrusions.

The campaign resembles another China-linked operation that Anthropic disclosed in November 2025, where attackers also used Claude Code to automate large-scale intrusions.

The recovered logs show that the attackers split the work between two AI models. Claude Code 2.1.165 handled execution by running Bash commands, managing long-running sessions, carrying out tasks in parallel, and creating phishing infrastructure. DeepSeek-v4-pro handled the planning by generating scripts, choosing attack techniques, and finding new ways to bypass defenses when earlier attempts failed.

“DeepSeek-v4-pro operates as the underlying reasoning model, handling attack logic, script generation, and decision-making.” continues the report. “In short, offensive logic is routed through a Chinese domestic LLM while leveraging Anthropic’s agentic execution infrastructure.”

A recovered CLAUDE.md file also contained instructions telling Claude Code to automatically create, test, and improve cloned phishing pages for multiple targets.

Session IDs in the logs confirmed the same infrastructure was used across different country-specific campaigns, with Taiwan operations saved to dedicated working directories. Timestamps on the files span June 8 through 12, 2026, and the three servers sharing SSH keys were actively maintained as recently as June 18-19, when all three reissued their ARL certificates together.

In Thailand, attackers used SQLMap to exploit a government administrative system through SQL injection, gained admin panel access, and deployed a web shell disguised as a GIF file for persistent command execution. The exfiltrated database held the names, national ID numbers, and job titles of government employees. The directory contained 980 files referencing this system alone, suggesting a lengthy and focused operation. Test entries the attackers created during the intrusion confirmed they had hands-on, interactive access to the data, not just automated extraction.

In Afghanistan, a government web application handling citizen complaint submissions was compromised. The attackers extracted source code, database credentials, encryption keys, and mail infrastructure code from a Laravel 5.8.38 installation, then used those credentials to build a custom Python exploit targeting Laravel’s deserialization mechanisms. Six distinct copied versions of the complaint submission form appeared in the directory. For a state actor, access to a live channel where citizens report grievances against government and institutions is a particular kind of intelligence prize.

In Taiwan, eight organizations in supply chain and defense-adjacent sectors were mapped and fingerprinted, with two successfully exploited. A chemical manufacturer was hit through SQL injection. A telecom and edge device manufacturer was compromised after attackers found hardcoded Supabase keys and Azure Logic App tokens in publicly accessible JavaScript files, giving them direct access to cloud infrastructure accounts. The reconnaissance script targeting these organizations ran DNS brute-forcing, certificate transparency queries, and HTTP service fingerprinting with an emphasis on VPN gateways, GitLab instances, and Jira environments.

The United States appeared at earlier stages of the operation rather than as a confirmed breach. NASA hosts launchpad.nasa[.]gov and ngis.nasa[.]gov were logged in network scanning output but not pursued further. Cloned pages impersonating the D.C. Council and Delaware County, Pennsylvania were recovered at varying levels of completion: the D.C. Council WordPress admin login page was fully built while the homepage was still missing images.

Hunt.io assessed the targeting of mid-tier government administrative bodies as consistent with documented Chinese intelligence collection priorities around procurement, vendor relationships, and policy visibility. The county contact form clone, specifically built to capture citizen submissions, fits that same pattern.

A parallel campaign hit financial services firms across Europe, Australia, and Asia. A CORS exploit page on one of the attacker-controlled servers successfully extracted WordPress administrator credentials from a large payment processing platform, with LinkedIn cross-referencing confirming the extracted account names matched real employees.

“In addition to the government-sector activity, the operators ran a parallel campaign against financial services firms across multiple regions. The clearest example being an attacker-developed CORS exploit page on 112.213.124[.]159 that successfully extracted WordPress administrator account data from a large payment processing platform.” states the report. “A cross-reference on the exposed accounts against public LinkedIn profiles, confirmed individuals with the same name as employees of the company.”

The 13 servers are all in Hong Kong, spread across four hosting providers: VMISS Inc., MEGA-II IDC, CTG Server Limited, and Antbox Networks Limited. Three share SSH host key fingerprints and ran identical ARL reconnaissance software serving the same default TLS certificate, with fields pointing to Shanghai. Two servers in the cluster also presented certificates self-identifying as “Gshell C2,” a previously undocumented C2 framework. Because those two servers overlap with the TencShell cluster, Hunt.io assesses with moderate confidence that Gshell is a second C2 framework operated in parallel by the same actors.

The malware recovered from the delivery ports was a previously unreported Linux/ARM 32-bit binary that communicates back to the same infrastructure hub over WebSocket. It’s capable of extracting Tencent QQ messaging credentials including SDK identifiers and cryptographic keys, enterprise messaging platform tokens, and cloud service access keys. A separate Linux/x86 variant uses the Go obfuscation tool garble to strip function names, but both variants share an identical 80-byte encryption key, pointing to a shared codebase across architectures.

“The campaign reflects an intermediate-to-advanced capability set: custom exploit development aimed at specific framework versions, multi-platform malware variants, and integration of LLMs for real-time attack assistance.” concludes the report. “Observable indicators: Simplified Chinese in code and documentation, Hong Kong infrastructure clustering, and multi-continent targeting, are consistent with China-based threat actor activity.”

Hunt.io notified the affected organizations and national CERTs on July 6, 2026, and held publication for a seven-day disclosure window. The full indicator set, including file hashes and network infrastructure, is in the original report.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, LLM)

Hackers Use Fake Claude Code Guide and AI PDFs to Spread AsyncRAT Malware

Hackers are using fake Claude Code guide and AI PDFs to spread AsyncRAT malware via Windows attack using PowerShell and Defender exclusions.

Fake Anthropic Sites Deliver Fileless Infostealer to Claude Code Users

Fake Anthropic websites are being used to target Claude Code users with a fileless infostealer campaign that steals browser credentials and evades detection.

Fake Claude Code Installer Targets Developers With Browser Credential Stealer

Researchers at Ontinue have discovered an undocumented malware campaign targeting developers with fake Claude Code installers to steal browser passwords and cookies.
  • ✇The Security Ledger
  • How Claude Planted Malicious Code In A Crypto-Trading App Paul Roberts
    A malicious campaign by North Korean state actors saw a malicious npm package dependency slipped into a crypto trading agent by an AI coding agent, according to a new report by ReversingLabs. The incident highlights a troubling new frontier in software supply chain attacks: hackers targeting developers...and the AI tools writing their code. The post How Claude Planted Malicious Code In A Crypto-Trading App appeared first on The Security Ledger with Paul F. Roberts.
     

How Claude Planted Malicious Code In A Crypto-Trading App

28 de Abril de 2026, 10:57

A malicious campaign by North Korean state actors saw a malicious npm package dependency slipped into a crypto trading agent by an AI coding agent, according to a new report by ReversingLabs. The incident highlights a troubling new frontier in software supply chain attacks: hackers targeting developers...and the AI tools writing their code.

The post How Claude Planted Malicious Code In A Crypto-Trading App appeared first on The Security Ledger with Paul F. Roberts.

Hackers Use Hidden Website Instructions in New Attacks on AI Assistants

Cybersecurity researchers at Forcepoint uncover new indirect prompt injection attacks that use hidden website code to exploit AI assistants like GitHub Copilot.

When Your AI Coding Plugin Starts Picking Your Dependencies: Marketplace Skills and Dependency Hijack in Claude Code

6 de Janeiro de 2026, 11:00

AI coding assistants are no longer just autocompleting lines of code, they are quietly making decisions for you. Tools like Claude Code are able to read projects, plan multi-step changes, install dependencies, and modify files with minimal human oversight. To make this possible, these assistants rely on plugin marketplaces, where third-party developers can enable ‘skills’ that teach the agent how to manage infrastructure, testing, and dependencies. Though powerful, the model requires a high degree of trust, thus bringing with it a new set of risks.

At a first glance, third-party marketplace plugins are harmless productivity boosters. Connect a marketplace and enable a plugin so your coding assistant becomes smarter about your stack. However, beneath the convenience is a security blind spot: These same skills often run with extremely high privilege and very little transparency on how they make decisions or where the code and dependencies are coming from. The code issue isn’t prompt manipulation or social engineering – it’s compromised automation.

A full technical blog post by SentinelOne’s own Prompt Security team breaks down how a single benign-looking plugin from an unofficial marketplace exposes a dependency management skill. When the developer asks the agent to install a common Python library, that skill quietly redirects the install to an attacker-controlled source, ensuring a trojanized version of the library is pulled into the project. While nothing looks wrong – the library imports cleanly, the example code runs without error – malicious code is now embedded into the environment, capable of exfiltrating secrets, monitoring traffic, or lying dormant until it is triggered at a later time.

What makes this especially concerning is persistence. Marketplace plugins are not one-off interactions. Once enabled, their skills remain available across sessions and will continue to shape how the agent behaves in the future. Rather than a ‘bad prompt’, this effect is more like compromising your package manager itself.

As AI-driven development workflows accelerate, plugin marketplaces and third-party skills are now part of the software supply chain whether teams realize it or not. If your coding assistant can fetch and execute code on your behalf, every plugin installed joins your trust boundary.

Read the full blog post here for a detailed walkthrough of the attack mechanics and learn why dependency skills are such a powerful, but under-modeled, risk.

Third-Party Trademark Disclaimer:

All third-party product names, logos, and brands mentioned in this publication are the property of their respective owners and are for identification purposes only. Use of these names, logos, and brands does not imply affiliation, endorsement, sponsorship, or association with the third-party.

❌
❌